Skip to main content

BIOS Management Overview

Overview

BIOS Management enables administrators to centrally configure and enforce BIOS settings on supported Windows devices directly from SureMDM. This helps organizations strengthen device security by controlling BIOS-level configurations such as supervisor passwords, boot order, and hardware controls without requiring manual intervention on individual devices. The feature supports BIOS management across supported OEMs, including Lenovo, HP, and Dell

Prerequisites

Before creating a BIOS configuration, ensure that:

  • BIOS Management is available exclusively to Enterprise tier customers and must be enabled for the SureMDM account.
  • Target devices are enrolled in SureMDM.
  • Devices are running SureMDM Windows Agent 6.32.0 and later.
  • The devices are Windows devices from a supported OEM validated fro BIOS Management.
  • Administrator credentials required for BIOS modifications are available, where applicable.
note

BIOS settings and available controls may vary depending on the OEM, device model, BIOS version, and firmware capabilities.

Important Considerations Before Deploying BIOS Configurations

Before deploying BIOS configurations to production devices, review the following considerations:

  • Deploying the same BIOS configuration to identical device models does not guarantee identical results or behavior. BIOS options and behavior can vary between different device models, hardware generations, and firmware versions. Therefore, do not assume that a configuration validated on one model will function identically on another.
  • BIOS configuration changes can affect device startup behavior, security settings, and overall device operability.
  • Certain BIOS settings may require a device reboot before the changes take effect.
  • Changes related to Lock boot order, preferred boot order, or password management should be validated in a test environment before production deployment.
  • BIOS passwords configured through SureMDM should be securely communicated to authorized end users when required. Failure to do so may prevent users from accessing or starting their devices.
  • Removing a BIOS configuration may not automatically revert all BIOS settings to their previous values. The resulting behavior depends on the configured Action on Config Removal setting.
  • Selecting Reset to Factory Settings during configuration removal may restore BIOS settings to factory defaults. On BitLocker-protected devices, this may trigger BitLocker recovery and require the recovery key.
  • Device support for BIOS settings may vary based on OEM, model, BIOS version, and firmware capabilities. Unsupported settings may be skipped or reported as failed during deployment.
  • Administrators should validate BIOS configurations on a limited set of devices before assigning them to larger device groups.
  • Unsupported devices and unsupported agent versions will not receive BIOS configurations.

Enabling BIOS Management

Before creating and deploying BIOS configurations, BIOS Management must be enabled at the account level.

To enable BIOS Management:

  1. Navigate to Account Settings > Windows Management > Miscellaneous.
  2. Under the BIOS Management section, enable the Enable BIOS Management option.
  3. Save the changes.
note

BIOS Management is supported on Windows devices running SureMDM Agent version 6.32.0 and later.

To access BIOS Management:

  1. Log in to the SureMDM Console.
  2. Navigate to Security > BIOS Management.
  3. Select the Configuration tab.

The Configuration page displays all BIOS configurations created within the account along with configuration details and management actions.

💬 Help us improve this documentation

Was this information useful?

Your feedback helps us keep our documentation accurate, up to date, and useful.